ID:11971 - Exploit for Path traversal in Atlassian Confluence Server - CVE-2019-3396
Published: September 19, 2025
Atlassian Confluence Server
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in the Widget Connector macro. A remote attacker can perform a server-side template injection and read arbitrary files on the system, leading to remote code execution.